Cyber Security News

SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets

A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access trojan and steal high-value data.

The investigation found no evidence that the software vendor distributed a trojanized build or that the incident stemmed from a supply-chain compromise.

Instead, attackers appear to have modified an existing software installation after deployment, placing the malicious folder under C:\ProgramData rather than the application’s ordinary installation path.

That distinction is critical: legitimate filenames and signed-looking program structures cannot be treated as proof of trust when DLL loading behavior has been altered.

The attack chain begins with ReportDump.exe, a legitimate-looking crash-reporting component configured to run through Windows Task Scheduler. When launched, it loads FrameworkBase.dll.

Attackers tampered with that DLL’s Import Address Table to add sdkcra.dll, a malicious loader, as an imported module.

This DLL sideloading-style execution path lets the implant run under the cover of a legitimate executable and its expected dependency chain.

The loader reads encrypted content from Activation.Desktop.db, decrypts it into assembly code, and abuses the Windows EnumSystemCodePagesW() callback parameter to execute that code.

The assembly then dynamically resolves 187 APIs by hash, frustrating static analysis and signature-based detection.

The SectopRAT payload is hidden in a legitimate software folder (Source : FortiGuard).

It subsequently reads encrypted data from pool.db, decrypts the payload in memory using a custom routine, initializes the .NET runtime, and invokes the SectopRAT entry point.

FortiGuard said in a report shared with GBhackers, the .NET-based malware, also known as ArechClient2, embedded within a tampered installation of legitimate digital audio workstation software from an Italian vendor.

SectopRAT Malware

The final payload is a 64-bit .NET executable protected through randomized names, control-flow flattening, and widespread use of the calli instruction, which invokes functions through pointers instead of normal method references.

These layers make reverse engineering substantially more difficult while also reducing the malware’s observable footprint on disk.

Once active, SectopRAT decrypts its command-and-control configuration and attempts to contact 98.142.252[.]140 over TCP port 15847.

The analysis of the dumped SectopRAT payload file in CFF Explorer, a PE analysis tool. Communications use AES encryption, with commands represented as JSON after decryption.

The SectopRAT payload analyzed in a PE analysis tool (Source : FortiGuard).

If its primary C2 is unavailable, the malware can request fallback infrastructure through 12 domains associated with Binance Smart Chain data endpoints, though Fortinet said it is unclear whether any of those domains were compromised.

The RAT supports 29 commands spanning remote administration, screen capture, process and file management, shell execution, rebooting, data export, plugin loading, and self-removal.

Its UnInstall command uses a delayed Windows shell command to delete the running payload after it exits, helping operators remove forensic evidence from a compromised host.

The most damaging functionality is triggered through the DeployBrowserKey command.

SectopRAT downloads an additional module, WbElevation.dll, then harvests saved credentials, URLs, cookies, autofill records, and stored payment-card information from Chromium-based browsers, Firefox-derived browsers, Microsoft Edge, Brave, Vivaldi, Yandex, and numerous other browser variants.

Display of the credentials collected from the Microsoft Edge browser (Source : FortiGuard).

It also targets Thunderbird, Steam, Battle.net, NVIDIA GeForce Experience, and cryptocurrency wallets including MetaMask, Coinbase Wallet, TronLink, Atomic Wallet, Exodus, Electrum, and Daedalus Mainnet.

For defenders, suspicious scheduled tasks invoking ReportDump.exe, altered FrameworkBase.dll imports, and unexpected software folders under C:\ProgramData should be treated as priority hunting leads.

Organizations should also block or investigate connections to the reported C2 infrastructure, identify affected files, reset browser-stored credentials and active sessions, and review cryptocurrency wallet exposure where compromised endpoints were used.

Fortinet maps the activity to techniques including browser credential theft, encrypted C2, screen capture, obfuscated files, fallback channels, and indicator removal.

IOCs

IOC TypeIndicator
C2 Server IP Address and Port98.142.252[.]140:15847
Backup Domain / URLhxxps://bsc-dataseed1.binance[.]org/
Backup Domain / URLhxxps://bsc-dataseed2.binance[.]org/
Backup Domain / URLhxxps://bsc-dataseed3.binance[.]org/
Backup Domain / URLhxxps://bsc-dataseed4.binance[.]org/
URLhxxp://98.142.252[.]140:9000/wmglb

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago